Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 9 Dec 2015 23:02:54 +0000 (UTC)
From:      Michael Moll <mmoll@FreeBSD.org>
To:        ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org
Subject:   svn commit: r403433 - in head/www/redmine: . files
Message-ID:  <201512092302.tB9N2ssY058729@repo.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: mmoll
Date: Wed Dec  9 23:02:54 2015
New Revision: 403433
URL: https://svnweb.freebsd.org/changeset/ports/403433

Log:
  www/redmine: update to 2.6.9
  
  PR:		205110
  MFH:		2015Q4
  Security:	CVE-2015-8346
  Security:	CVE-2015-8473
  Security:	CVE-2015-8474
  Security:	CVE-2015-8477

Modified:
  head/www/redmine/Makefile
  head/www/redmine/distinfo
  head/www/redmine/files/extra-patch-Gemfile
  head/www/redmine/files/patch-Gemfile
  head/www/redmine/pkg-plist

Modified: head/www/redmine/Makefile
==============================================================================
--- head/www/redmine/Makefile	Wed Dec  9 21:23:01 2015	(r403432)
+++ head/www/redmine/Makefile	Wed Dec  9 23:02:54 2015	(r403433)
@@ -2,8 +2,7 @@
 # $FreeBSD$
 
 PORTNAME=	redmine
-PORTVERSION=	2.6.3
-PORTREVISION=	4
+PORTVERSION=	2.6.9
 CATEGORIES=	www
 MASTER_SITES=	http://www.redmine.org/releases/
 
@@ -16,14 +15,16 @@ LICENSE_FILE=	${WRKSRC}/doc/COPYING
 RUN_DEPENDS=	rubygem-builder>=3.0.0:${PORTSDIR}/devel/rubygem-builder \
 		rubygem-bundler>=0:${PORTSDIR}/sysutils/rubygem-bundler \
 		rubygem-coderay>=1.0.9:${PORTSDIR}/textproc/rubygem-coderay \
-		rubygem-fastercsv>=1.5.0:${PORTSDIR}/devel/rubygem-fastercsv \
 		rubygem-i18n>=0.7.0:${PORTSDIR}/devel/rubygem-i18n \
+		rubygem-jquery-rails>=3.1.4:${PORTSDIR}/www/rubygem-jquery-rails \
+		rubygem-mime-types>=0:${PORTSDIR}/misc/rubygem-mime-types \
 		rubygem-net-ldap>=0.3.1:${PORTSDIR}/net/rubygem-net-ldap \
 		rubygem-rack-openid>=0:${PORTSDIR}/www/rubygem-rack-openid \
-		rubygem-rails>=3.2.16:${PORTSDIR}/www/rubygem-rails \
+		rubygem-ruby-openid>=2.3.0:${PORTSDIR}/net/rubygem-ruby-openid \
+		rubygem-rails>=3.2.22:${PORTSDIR}/www/rubygem-rails \
 		rubygem-rake>=0:${PORTSDIR}/devel/rubygem-rake \
 		rubygem-rbpdf>=0:${PORTSDIR}/print/rubygem-rbpdf \
-		rubygem-redcarpet>=3.0:${PORTSDIR}/textproc/rubygem-redcarpet \
+		rubygem-redcarpet>=3.3.2:${PORTSDIR}/textproc/rubygem-redcarpet \
 		rubygem-request_store>=1.1.0:${PORTSDIR}/devel/rubygem-request_store \
 		rubygem-rubytree>=0:${PORTSDIR}/devel/rubygem-rubytree
 
@@ -53,7 +54,7 @@ MYSQL2_RUN_DEPENDS=	rubygem-mysql2>=0:${
 PASSENGER_RUN_DEPENDS=	passenger-config:${PORTSDIR}/www/rubygem-passenger
 POSTGRESQL_RUN_DEPENDS=	rubygem-pg>=0:${PORTSDIR}/databases/rubygem-pg
 RMAGIC_EXTRA_PATCHES_OFF=	${FILESDIR}/extra-patch-Gemfile
-RMAGIC_RUN_DEPENDS=	rubygem-rmagick>=2.0.0:${PORTSDIR}/graphics/rubygem-rmagick
+RMAGIC_RUN_DEPENDS=	rubygem-rmagick>=2.13.4:${PORTSDIR}/graphics/rubygem-rmagick
 THIN_EXTRA_PATCHES=	${FILESDIR}/extra-patch-thin-Gemfile
 THIN_RUN_DEPENDS=	thin:${PORTSDIR}/www/rubygem-thin
 THIN_SUB_LIST=		WWWOWN=${WWWOWN} WWWGRP=${WWWGRP}

Modified: head/www/redmine/distinfo
==============================================================================
--- head/www/redmine/distinfo	Wed Dec  9 21:23:01 2015	(r403432)
+++ head/www/redmine/distinfo	Wed Dec  9 23:02:54 2015	(r403433)
@@ -1,2 +1,2 @@
-SHA256 (redmine-2.6.3.tar.gz) = 33b41b78388de338a97f39bedfb45c3c9e76794d84a99736f113281a3a3caac2
-SIZE (redmine-2.6.3.tar.gz) = 2121625
+SHA256 (redmine-2.6.9.tar.gz) = 15cafc3983e0520c3ecc6105ef33031f55b1dc2b21270d092938562b47362d4c
+SIZE (redmine-2.6.9.tar.gz) = 2127454

Modified: head/www/redmine/files/extra-patch-Gemfile
==============================================================================
--- head/www/redmine/files/extra-patch-Gemfile	Wed Dec  9 21:23:01 2015	(r403432)
+++ head/www/redmine/files/extra-patch-Gemfile	Wed Dec  9 23:02:54 2015	(r403433)
@@ -9,9 +9,9 @@
 -    # RMagick 2 supports ruby 1.9
 -    # RMagick 1 would be fine for ruby 1.8 but Bundler does not support
 -    # different requirements for the same gem on different platforms
--    gem "rmagick", (RUBY_VERSION < "1.9" ? "2.13.3" : ">= 2.0.0")
+-    gem "rmagick", (RUBY_VERSION < "1.9" ? "2.13.3" : "~> 2.13.4")
 -  end
 -
    # Optional Markdown support, not for JRuby
    group :markdown do
-     # TODO: upgrade to redcarpet 3.x when ruby1.8 support is dropped
+     gem "redcarpet", (RUBY_VERSION < "1.9" ? "~> 2.3.0" : "~> 3.3.2")

Modified: head/www/redmine/files/patch-Gemfile
==============================================================================
--- head/www/redmine/files/patch-Gemfile	Wed Dec  9 21:23:01 2015	(r403432)
+++ head/www/redmine/files/patch-Gemfile	Wed Dec  9 23:02:54 2015	(r403433)
@@ -1,21 +1,23 @@
---- Gemfile.orig	2015-05-25 16:10:44 UTC
+--- Gemfile.orig	2015-12-09 20:52:29 UTC
 +++ Gemfile
-@@ -1,24 +1,24 @@
+@@ -1,25 +1,25 @@
  source 'https://rubygems.org'
  
--gem "rails", "3.2.21"
+-gem "rails", "3.2.22"
 +gem "rails", "~> 3.2"
- gem "jquery-rails", "~> 3.1.1"
+ gem "rack-cache", "1.2" if RUBY_VERSION < "1.9.3"
+ gem "jquery-rails", "~> 3.1.4"
  gem "coderay", "~> 1.1.0"
  gem "fastercsv", "~> 1.5.0", :platforms => [:mri_18, :mingw_18, :jruby]
  gem "builder", ">= 3.0.4"
 -gem "request_store", "1.0.5"
 +gem "request_store", ">= 1.0.5"
  gem "mime-types"
- gem "rbpdf", "~> 1.18.5"
+-gem "rbpdf", "~> 1.18.7"
++gem "rbpdf", ">= 1.18.7"
  
 -gem "i18n", "~> 0.6.11"
-+gem "i18n", "~> 0.7.0"
++gem "i18n", ">= 0.6.11"
  
  # Optional gem for LDAP authentication
  group :ldap do
@@ -26,20 +28,11 @@
  # Optional gem for OpenID authentication
  group :openid do
 -  gem "ruby-openid", "~> 2.3.0", :require => "openid"
-+  gem "ruby-openid", "~> 2.7", :require => "openid"
++  gem "ruby-openid", ">= 2.3.0", :require => "openid"
    gem "rack-openid"
  end
  
-@@ -34,7 +34,7 @@ platforms :mri, :mingw do
-   # Optional Markdown support, not for JRuby
-   group :markdown do
-     # TODO: upgrade to redcarpet 3.x when ruby1.8 support is dropped
--    gem "redcarpet", "~> 2.3.0"
-+    gem "redcarpet", "~> 3.0"
-   end
- end
- 
-@@ -81,23 +81,6 @@ else
+@@ -82,23 +82,6 @@ else
    warn("Please configure your config/database.yml first")
  end
  
@@ -49,14 +42,14 @@
 -end
 -
 -group :test do
+-  gem "minitest"
+-  gem "test-unit", "~> 3.0"
 -  gem "shoulda", "~> 3.3.2"
 -  gem "shoulda-matchers", "1.4.1"
 -  gem "mocha", "~> 1.0.0", :require => 'mocha/api'
 -  if RUBY_VERSION >= '1.9.3'
 -    gem "capybara"
 -    gem "selenium-webdriver"
--    # building ffi 1.9.7 fails in Ubuntu: https://github.com/ffi/ffi/issues/414
--    gem "ffi", "1.9.6"
 -  end
 -end
 -

Modified: head/www/redmine/pkg-plist
==============================================================================
--- head/www/redmine/pkg-plist	Wed Dec  9 21:23:01 2015	(r403432)
+++ head/www/redmine/pkg-plist	Wed Dec  9 23:02:54 2015	(r403433)
@@ -1370,7 +1370,7 @@
 %%WWWDIR%%/public/javascripts/i18n/datepicker-vi.js
 %%WWWDIR%%/public/javascripts/i18n/datepicker-zh-CN.js
 %%WWWDIR%%/public/javascripts/i18n/datepicker-zh-TW.js
-%%WWWDIR%%/public/javascripts/jquery-1.11.1-ui-1.11.0-ujs-3.1.1.js
+%%WWWDIR%%/public/javascripts/jquery-1.11.1-ui-1.11.0-ujs-3.1.4.js
 %%WWWDIR%%/public/javascripts/jstoolbar/jstoolbar-textile.min.js
 %%WWWDIR%%/public/javascripts/jstoolbar/jstoolbar.js
 %%WWWDIR%%/public/javascripts/jstoolbar/lang/jstoolbar-ar.js



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201512092302.tB9N2ssY058729>